{"id":"CVE-2020-14004","details":"An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cmd. /run/icinga2 is under control of an unprivileged user by default. If /run/icinga2/cmd is a symlink, then it will by followed and arbitrary files can be changed to mode 2750 by the unprivileged icinga2 user.","modified":"2026-07-08T05:53:36.995944339Z","published":"2020-06-12T16:15:10.387Z","related":["SUSE-SU-2022:3725-1","openSUSE-SU-2020:1820-1","openSUSE-SU-2024:10856-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"15.0-sp1"},{"last_affected":"15.0-sp1"},{"introduced":"15.0-sp2"},{"last_affected":"15.0-sp2"}],"source":"CPE_STRING","vendor_product":"opensuse:backports_sle","cpes":["cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*","cpe:2.3:a:opensuse:backports_sle:15.0:sp2:*:*:*:*:*:*"]},{"cpes":["cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*","cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"15.1"},{"last_affected":"15.1"},{"introduced":"15.2"},{"last_affected":"15.2"}],"source":"CPE_STRING","vendor_product":"opensuse:leap"}]},"references":[{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00014.html"},{"type":"ADVISORY","url":"https://github.com/Icinga/icinga2/compare/v2.12.0-rc1...master"},{"type":"ADVISORY","url":"https://github.com/Icinga/icinga2/releases"},{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2020-14004"},{"type":"FIX","url":"https://github.com/Icinga/icinga2/pull/8045/commits/2f0f2e8c355b75fa4407d23f85feea037d2bc4b6"},{"type":"EVIDENCE","url":"http://www.openwall.com/lists/oss-security/2020/06/12/1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/icinga/icinga2","events":[{"introduced":"30384a4340011723869969e76a3dd2801786cf2e"},{"last_affected":"911c14fad87719aa6bc95b17ddf579acd31acf83"},{"introduced":"71cefb9ea4e5f0f824ca78bb92ff1332b0165726"},{"last_affected":"71cefb9ea4e5f0f824ca78bb92ff1332b0165726"}],"database_specific":{"extracted_events":[{"introduced":"2.0.0"},{"last_affected":"2.11.3"},{"introduced":"2.12.0-rc1"},{"last_affected":"2.12.0-rc1"}],"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:icinga:icinga:*:*:*:*:*:*:*:*","cpe:2.3:a:icinga:icinga:2.12.0:rc1:*:*:*:*:*:*"]}}],"versions":["2.12.0-rc1","v2.11.0","v2.11.3","v2.12.0-rc1","v2.11.2","v2.11.1","v2.11.0-rc1","v2.10.1","v2.10.0","v2.9.0","v2.7.0","v2.6.1","v2.6.0","v2.5.0","v2.4.0","v2.3.0","v2.2.0","v2.1.1","v2.1.0","v2.0.2","v2.0.1","v2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-14004.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/icinga/icingaweb2","events":[{"introduced":"ee1ee5af84d32c4493365959aa8a4322a34582e4"},{"last_affected":"f917436a894c1f4148a9c3d6a27f9c20f204e44f"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:icinga:icinga:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.0.0"},{"last_affected":"2.11.3"}]}}],"versions":["v2.11.3","v2.11.2","v2.11.1","v2.11.0","v2.10.0","v2.8.0","v2.8.0-rc1","v2.7.1","v2.7.0","v2.6.2","v2.6.1","v2.6.0","v2.5.3","v2.5.2","v2.5.1","v2.5.0","v2.4.0-2","v2.4.0","v2.3.4","v2.3.3","v2.3.2","v2.2.0","v2.1.2","v2.3.1","v2.3.0","v2.1.1","v2.1.0","v2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-14004.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}